ISO 22301 was first introduced by the International Organization for Standardization (ISO) in 2012 to address global business continuity needs. It built on earlier standards but provided a comprehensive framework for organisations of all sizes and industries.
The standard was updated in 2019 to reflect the evolving landscape of business continuity challenges. The latest version also integrates modern risk management practices.
Thanks to its widespread adoption, ISO 22301 has become a key business management system standard.
ISO 22301 guides you in setting up an effective Business Continuity Management System (BCMS) for your organisation. The standard focuses on several key areas to support operational resilience:
These requirements help you create a robust framework that strengthens your organisation’s ability to maintain operations during disruptions.
ISO 22301 certification demonstrates that your organisation’s BCMS meets the ISO 22301 standard. It shows customers, partners, and regulators of your business’s ability to maintain operations during disruptions.
An independent body evaluates your BCMS’s processes, plans, and response strategies. If they meet ISO 22301 standards, certification is achieved. This must be renewed periodically to maintain compliance.
Certification builds trust with stakeholders, meets contractual obligations, and provides a competitive advantage by demonstrating your commitment to resilience.
To achieve certification, follow these steps:
Thorough preparation can mean achieving certification is manageable for your organisation.
Access our free ISO 22301 resources designed to help you
discover, understand and build a Business Continuity
Management System to ISO 22301 standard.
Access a list of third-party ISO consultants who may be able to support your needs.
Find a Consultant
ISO 22301 is an international standard for Business Continuity Management Systems (BCMS). It provides a framework for organisations to improve their business resilience and minimise the impact of disruptions.
The ISO element stands for the ‘International Organization for Standardization’ – an independent, non-governmental international organisation that develops and publishes business management system standards.
The International Organization for Standardization (ISO) assigns each of its standards a number – in this case, the standard’s number is ‘22301’. The ISO numbering system categorises and identifies different standards within its catalogue.
ISO 22301 and ISO 27001 are both standards published by the International Organization for Standardization, however, they focus on very different areas of business operations. While both standards involve risk management and require leadership commitment, ISO 22301 is centred around business continuity, whereas ISO 27001 is focused on information security.
Organisations sometimes implement both standards together to manage risks related to business operations and information security.
The ISO 22301 standard can help organisations with the following key points and more:
ISO 22301 itself does not prescribe specific policies, but it requires organisations to establish policies as part of their BCMS. These policies set the framework and direction for how business continuity will be managed.
For example, one important policy that must be established is the Business Continuity Policy. This outlines the organisation’s commitment to maintaining business continuity and resilience. It should define the scope, objectives, and principles of the BCMS.
Organisations might also create other policies around the following to meet requirements:
These policies should be tailored to the specific needs and context of the organisation and are typically approved by senior management to demonstrate leadership commitment to business continuity.